CVE-2021-42287
A Microsoft Active Directory vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
A Microsoft Active Directory vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft's SMBv1 server vulnerability (CVE-2017-0148) allowed remote code execution and was actively exploited, often linked to ransomware attacks, demonstrating a critical failure to secure legacy protocols and data transfers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Internet Explorer use-after-free vulnerability allowed remote code execution via crafted websites and is actively exploited in ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Office vulnerability allowed authenticated users to inject SQL and potentially execute arbitrary code remotely, actively exploited in ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Java SE vulnerabilities are actively exploited and linked to ransomware attacks, demonstrating a persistent risk for DIB organizations using outdated Java installations.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting DIB organizations using Windows systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft DirectX Graphics Kernel vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting DIB systems relying on DirectX drivers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft DirectX Graphics Kernel vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting DIB systems relying on DirectX drivers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows flaw allowed local privilege escalation via crafted applications, actively exploited and linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows flaw allowed attackers to escalate privileges by running crafted applications, actively exploited and linked to ransomware campaigns.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix ShareFile allowed unauthenticated attackers to remotely compromise storage zones controllers, actively exploited and linked to ransomware activity.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe ColdFusion's directory traversal vulnerability allowed attackers to read arbitrary files via the administrator console, and is currently being exploited in the wild, often linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A flaw in Palo Alto Networks' PAN-OS allowed attackers to bypass authentication, potentially granting unauthorized access to networks and systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware Tanzu Spring Data Commons contained a remote code execution vulnerability actively exploited in ransomware attacks, impacting DIB organizations using this software stack.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows Print Spooler vulnerability allowed privilege escalation and was actively exploited, likely contributing to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A critical Windows vulnerability allowed remote code execution via SMBv1, actively exploited and linked to ransomware attacks, demonstrating a failure to patch a known risk.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allowed attackers to escalate privileges, actively exploited and linked to ransomware campaigns.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft's Task Scheduler had a privilege escalation vulnerability actively exploited by ransomware actors, allowing attackers to gain elevated system access.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allowed attackers to escalate privileges, actively exploited and linked to ransomware campaigns.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allowed attackers to escalate privileges, actively exploited and linked to ransomware campaigns.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows flaw allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting DIB systems relying on Windows infrastructure.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allowed attackers to escalate privileges, actively exploited and linked to ransomware campaigns.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows kernel vulnerability allowed attackers to escalate privileges and execute arbitrary code, actively exploited in ransomware campaigns and impacting DIB organizations using Windows systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Win32k vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting Windows systems widely used in the DIB.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Win32k vulnerability allowed local privilege escalation, actively exploited and linked to ransomware attacks, impacting Windows OS and Server deployments.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows UPnP service vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allowed attackers to escalate privileges, actively exploited and linked to ransomware campaigns.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allowed privilege escalation on AppX Deployment Servers, actively exploited and linked to ransomware attacks, impacting DIB organizations using Windows systems for software deployment and management.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows flaw allowed attackers to gain elevated privileges by manipulating hard links, actively exploited and linked to ransomware campaigns.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A decade-old Adobe BlazeDS vulnerability is actively exploited, potentially exposing sensitive information in systems using LifeCycle and ColdFusion applications.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Java SE's Concurrency component had a remotely exploitable arbitrary code execution vulnerability, actively targeted by ransomware actors, highlighting the risk of outdated software in DIB environments.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server vulnerabilities allowed attackers to impersonate users, linked to ransomware activity and actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Windows Installer vulnerability allowed privilege escalation and was actively exploited in ransomware attacks, impacting DIB organizations reliant on Windows systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player, now defunct, contained a critical, actively exploited remote code execution vulnerability, leaving systems perpetually exposed to attack.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A critical Adobe Reader/Acrobat vulnerability (CVE-2010-0188) allowed arbitrary code execution and is actively exploited, often linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allowed attackers to escalate privileges to administrator level, actively exploited and linked to ransomware campaigns.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player vulnerabilities allowed attackers to execute arbitrary code via malicious SWF files, and no patches are available due to the product's end-of-life status.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Java SE allowed remote code execution via a known vulnerability actively exploited in ransomware attacks, demonstrating a failure to patch critical systems promptly.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A critical, actively exploited vulnerability in Adobe Acrobat and Reader allows for potential remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows Server vulnerability allowed local attackers to escalate privileges and execute arbitrary code, actively exploited and linked to ransomware activity.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.